setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through config.platform.php, and insufficiently constrains those values before incorporating them into generated shell or PowerShell setup scripts, allowing command injection on a GitHub Actions runner when workflows such as pull_request_target check out attacker-controlled contents before invoking setup-php. This issue is fixed in version 2.37.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept for CVE-2026-46420, a command injection vulnerability in the GitHub Action shivammathur/setup-php. The exploit is not a standalone network service exploit; it targets CI/CD execution flow by abusing repository-controlled metadata consumed by a third-party action. The core idea is that a vulnerable workflow checks out attacker-controlled pull request content and then runs setup-php@2.37.0 in a pull_request_target workflow. If setup-php reads the PHP version from composer.json, a malicious value such as "8.2;<COMMAND> #" is injected into generated shell commands and executed on the GitHub Actions runner. Repository structure is minimal and purpose-built: README.md explains the vulnerability, affected/fixed versions, exploitation steps, and payload format; .github/workflows/poc.yml is the main executable PoC workflow showing the vulnerable trigger and validation logic; composer.json is the benign baseline file; attacker/composer.json contains the malicious payload; demo-app/.env.example is the file altered to demonstrate successful command execution. The workflow prints the env file before and after running setup-php, diffs it, and greps for FEATURE_FLAG=modified-by-poc to confirm exploitation. Main exploit capability: arbitrary shell command execution in the CI runner context. The included payload uses sed to modify demo-app/.env.example, but the README explicitly documents interchangeable commands such as touch, printf redirection, and id, confirming general command execution rather than a single fixed effect. Because the exploit depends on a vulnerable GitHub Actions configuration and attacker influence over repository contents in a PR, the primary attack vectors are supply-chain/cloud CI abuse rather than direct network exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.